7. Sustain: Monitoring and Auditing Program Performance Flashcards
Define Metric
provides data that helps to answer specific questions about business operations.
An organization should develop privacy metrics
Types of Metric Audiences (PST)
Primary Audiences: legal & privacy officers, CIO, CISO, privacy mangers and executives.
Secondary Audiences: department owners, HR, CFO, HIPPA Officer, IG’s and training organizations.
Tertiary Audiences: external watchdog groups, sponsors and stockholders.
Terms: Metric Owner & ROI Analysis
Metric Owner - responsible for managing the metric throughout its life cycle.
ROI Analysis - provides quantitative measurement for the costs, benefits, strengths and weaknesses of an organization’s privacy controls in order to maximize the benefits of investments that prevent loss.
4 Ways to Analyze Primary Metrics (TRRM)
- Trend Analysis
- Return of Investment (ROI)
- Business Resiliency
- Program Maturity
Trend, ROI, Resiliency, Maturity (TRRM)
Monitor Privacy Programs - to track compliance and risk, organizations alignment with regulatory and legislative changes, and vulnerabilities in the internal and external environment.
- Tracking Compliance and Risk
- Tracking Regulatory and Legislative Changes
- Tracking Environmental Vulnerabilities
Forms of Monitoring - Privacy Program
- Active Scanning Tools i.e. Data Loss Prevention
- Audit Activities
- Breach Monitoring, Detection, & Notification
- Complaint Monitoring
- Data Retention
- Control-Based Monitoring
- HR Practices of Hiring & Terminations
- Internal & External Conditions
- Regulation-Based Monitoring
What is Privacy Audit
Privacy Audit - involves monitoring and measuring privacy practices to comply with laws, regulations, consent orders, and industry practices.
Audit Answers 2 Questions (OC)
- Privacy Operation do what they were designed to do?
- Controls correctly managed?
Program Maturity Models, different types:
Ad Hoc - informal process
Repeatable - procedures and process, not fully documented or covered
Defined - fully documented, implemented, and cover all relevant aspects
Managed - reviews are conducted to assess control effectiveness
Optimized - regular review and feedback for continual improvement
GDPR mandated metrics for reporting
DPIAs conducted
DSARs received
Complaints received
Data security incidents
How many elevated to notifications of DPAs